Uploaded image for project: 'OpenShift Pipelines'
  1. OpenShift Pipelines
  2. SRVKP-8172

Unauthenticated access to metrics exposed by OpenShift Pipelines operator

XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Unresolved
    • Icon: Critical Critical
    • None
    • None
    • Operator
    • False
    • Hide

      None

      Show
      None
    • False

      Slack support thread: https://redhat-internal.slack.com/archives/CSPS1077U/p1752722551352459 

      Description of problem:

      The metrics exposed by OpenShift Pipelines controllers do not require any authentication and hence pose security risk in Multitenant environments.

      http://<IP_of_tekton-triggers-controller-*_POD>:9000/metrics  --> "openshift-triggers-monitor"
      http://<IP_of_tekton-pipelines-controller-*_POD>:9090/metrics  --> "openshift-pipelines-monitor"
      http://<IP_of_tekton-chains-controller-*_POD>:9090/metrics  --> "openshift-chains-monitor"
      http://<IP_of_openshift-pipelines-operator-*_POD>:9090/metrics  --> "openshift-pipelines-operator-monitor" 

      Prerequisites (if any, like setup, operators/versions):

      Steps to Reproduce

       # <steps>

       

      Actual results:

      Expected results:

      Reproducibility (Always/Intermittent/Only Once):

      Acceptance criteria: 

       

      Definition of Done:

      Build Details:

      Additional info (Such as Logs, Screenshots, etc):

       

       *

              rh-ee-shubbhar Shubham Bhardwaj
              rhn-support-jyarora Jyotsana Arora
              Votes:
              1 Vote for this issue
              Watchers:
              10 Start watching this issue

                Created:
                Updated: